Vulnerability Description
API calls in the Translation API feature in Systran Pure Neural Server before 9.7.0 allow a threat actor to use the Systran Pure Neural Server as a Denial-of-Service proxy by sending a large amount of translation requests to a destination host on any given TCP port regardless of whether a web service is running on the destination port.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Systransoft | Pure Neural Server | < 9.7.0 |
References
- https://grave-rose.medium.com/two-systran-vulnerabilities-and-their-exploits-8bcExploitThird Party Advisory
- https://www.systransoft.com/translation-products/systran-pure-neural-server/Product
- https://grave-rose.medium.com/two-systran-vulnerabilities-and-their-exploits-8bcExploitThird Party Advisory
- https://www.systransoft.com/translation-products/systran-pure-neural-server/Product
FAQ
What is CVE-2020-29540?
CVE-2020-29540 is a vulnerability with a CVSS score of 7.5 (HIGH). API calls in the Translation API feature in Systran Pure Neural Server before 9.7.0 allow a threat actor to use the Systran Pure Neural Server as a Denial-of-Service proxy by sending a large amount of...
How severe is CVE-2020-29540?
CVE-2020-29540 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-29540?
Check the references section above for vendor advisories and patch information. Affected products include: Systransoft Pure Neural Server.